slides(tappaas): correct the rewrite history, note the other instances
All checks were successful
Build docs site / build (push) Successful in 46s
Build slides / build (push) Successful in 1m6s

The ADR-007 rewrite was the move from a flat pile of sequenced scripts to the
manager/controller paradigm — not the dependsOn change. That was an earlier
and separate rewrite, ADR-003: a plain install.sh per module replaced by
dependsOn/provides contracts the platform resolves into an order.

Also: a closing line on the hardware slide that this is one of five known
instances, and the September 2025 gap now answers itself.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Lars Rossen 2026-08-25 18:02:55 +02:00
parent d08e8ad743
commit e1d69309b8

View file

@ -19,7 +19,7 @@ th, td { padding: 0.2em 0.55em; }
code.todo { color: #ff8a80; font-weight: 600; } code.todo { color: #ff8a80; font-weight: 600; }
/* Mermaid renders at its natural size, which is far too small on a projector. */ /* Mermaid renders at its natural size, which is far too small on a projector. */
div.mermaid { display: flex; justify-content: center; width: 100%; } div.mermaid { display: flex; justify-content: center; width: 100%; }
div.mermaid svg { width: 100% !important; height: auto !important; max-height: 500px; } div.mermaid svg { width: 100% !important; height: auto !important; max-height: 460px; }
section.diagram h2 { margin-bottom: 0.1em; } section.diagram h2 { margin-bottom: 0.1em; }
/* Hand-drawn diagrams (inline SVG) get the same full-width treatment. */ /* Hand-drawn diagrams (inline SVG) get the same full-width treatment. */
section.diagram > svg { display: block; width: 100%; height: auto; max-height: 520px; margin: 0 auto; } section.diagram > svg { display: block; width: 100%; height: auto; max-height: 520px; margin: 0 auto; }
@ -143,8 +143,13 @@ flowchart TB
sw --- modem sw --- modem
``` ```
This is one basement. **There are 4 other known instances of TAPPaaS.**
<!-- <!--
Every number here was read off the running cluster, not a wiki page. Every number here was read off the running cluster, not a wiki page.
The last line is deliberately understated — it sets up the sharing argument
in The Bad, and the Community repo in the next slide. Five sites is not a
movement yet; it is proof the thing installs somewhere that is not here.
Worth saying out loud: only tanka1 on tappaas1 is a mirror. tappaas2 and Worth saying out loud: only tanka1 on tappaas1 is a mirror. tappaas2 and
tappaas3 run single NVMe — deliberate, they are rebuildable from backup. tappaas3 run single NVMe — deliberate, they are rebuildable from backup.
The 10G links are direct-attach copper; tappaas1 and tappaas3 have a second The 10G links are direct-attach copper; tappaas1 and tappaas3 have a second
@ -356,7 +361,7 @@ What it actually cost.
**September–October 2025: 15 commits in two months.** **September–October 2025: 15 commits in two months.**
`TODO: what actually happened here — say it plainly, it is the most relatable slide in the deck` I was on vacation.
The lesson I take from it: a self-hosted platform that needs *you* every week The lesson I take from it: a self-hosted platform that needs *you* every week
is not a platform, it is a pet. is not a platform, it is a pet.
@ -446,22 +451,26 @@ TODO: your own hours-per-week number makes the concession land harder.
- **The predecessor.** I ran a hand-built setup for a few years before TAPPaaS - **The predecessor.** I ran a hand-built setup for a few years before TAPPaaS
existed. Every design decision here is an argument I already lost once, at home. existed. Every design decision here is an argument I already lost once, at home.
- **Rewrite 1 — ADR-007.** Foundation modules used to be *numbered*: - **Rewrite 1 — ADR-003.** Every module was a plain `install.sh` you ran in the
`05-ProxmoxNode`, `10-firewall`, `30-tappaas-cicd`. The number **was** the right order, by hand. Replaced by `dependsOn` / `provides` contracts, resolved
install order. Retired: order is now computed from `dependsOn`. into an install order by the platform.
- **Rewrite 2 — ADR-014.** Zone tiers lived in prose in a README. Now `tier` and - **Rewrite 2 — ADR-007.** The flat pile of sequenced scripts became a
`isolated` are state, and four invariants are machine-checked on every reconcile. **manager / controller** paradigm: 7 TypeScript managers that own intent,
6 controllers that do the live I/O against OPNsense, Authentik, Proxmox, the switch.
Both times the same lesson: something I had encoded as a **convention** Both times the same mistake: I had written as a **sequence of steps**
had to become a **declaration**. what needed to be a **structure** — dependencies the first time, roles the second.
`TODO: name the predecessor, and say how long you ran it` `TODO: name the predecessor, and say how long you ran it`
<!-- <!--
This is the credibility slide. Do not soften the "No" — an audience that has This is the credibility slide. Do not soften the "No" — an audience that has
just been told you gave an AI root needs to hear that you rebuild things when just been told you gave an AI root needs to hear that you rebuild things when
they are wrong. The ADR-007 and ADR-014 stories are both in the repo if they are wrong.
anyone wants to check. Both ADRs are in the repo, and ADR-007f was written by Erik, not me — which
is the two-reviewer rule from Guardrail 1 doing its job in public.
If you want a third: ADR-014 recast zone tiers from README prose into checked
state, and its own changelog lists four things the draft got wrong.
--> -->
--- ---